mirror of
https://github.com/apache/struts.git
synced 2026-08-11 01:27:14 +00:00
4f3fd69aa6
* WW-5632 docs: add commons-fileupload2 milestone-hardening design spec Design for hardening the commons-fileupload2 dependency against milestone binary-incompatibility (manage -core, activate a scoped enforcer rule, add a runtime API guard in AbstractMultiPartRequest). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * WW-5632 docs: add implementation plan for fileupload2 milestone hardening Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * WW-5632 build(deps): manage commons-fileupload2-core alongside jakarta-servlet6 Pin both commons-fileupload2 artifacts to a single commons-fileupload2.version property so the volatile -core API can no longer skew from -jakarta-servlet6 in the reactor. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * WW-5632 build: enforce a single commons-fileupload2 version Activate maven-enforcer-plugin (previously dormant in pluginManagement) with a fileupload-scoped bannedDependencies rule so any divergent commons-fileupload2 version fails the build early. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * WW-5632 fix(fileupload): fail fast on incompatible commons-fileupload2 API Verify once per JVM that the fileupload size-limit setters exist and throw a clear StrutsException reporting the core/jakarta version skew, replacing an opaque deep-stack NoSuchMethodError in downstream runtimes. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * WW-5632 fix(fileupload): make API-verification guard static Resolve Sonar java:S2696 (instance method writing a static field) by making ensureFileUploadApiVerified() static; verification is JVM-global. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>